BASE / PRIVACY
Privacy Notice.
Effective July 28, 2026
The short version
Base reads the Apple Health data its features need and processes your health data on your devices. If you explicitly start a workout in Base on Apple Watch, Base saves that workout to Apple Health. Base Cardio LLC does not receive that health data. We do not sell personal information, serve ads, or track you across apps or websites. The app does send us information about how it is used, along with crash reports, and that is on unless you turn it off — the switch is in the app under You → App settings → Privacy, and none of it ever includes your health data. Two other things reach us only if you choose them: joining the website waitlist, and emailing support from inside the app. Base never puts your health data into that email and never sends it for you — though anything you type yourself is up to you. Apple also passes us some things on its own: crash reports, if you have chosen to share them with developers, and tester information if you use TestFlight. Each of those is described below.
Who we are and what this covers
This notice explains how Base Cardio LLC handles information in the Base iPhone app, Apple Watch app, widgets, complications, and the website at basecardio.com. Base Cardio LLC is the operator and privacy contact.
Base Cardio LLC605 West 9th Street #1058
Austin, TX 78701
United States
hello@basecardio.com
What the app reads and writes
With your permission, Base reads the following categories from Apple Health:
- Heart rate to calculate time within your selected Zone 2 range.
- Active energy to recognize workout energy recorded by Apple Watch. Apple, not Base, calculates calories and Fitness-ring progress.
- Resting heart rate to show a trend and, if you enable Automatic Karvonen, calibrate your range.
- Date of birth to determine age for an age-based heart-rate range.
- Workouts to attribute qualifying minutes to activities such as walks, runs, rides, and hikes.
- Apple Exercise Time to identify qualifying everyday activity outside recorded workouts.
Apple Health is the source of these categories. Base does not request sleep, nutrition, reproductive health, clinical records, location routes, or Health categories that are not needed for these features.
If you explicitly start a workout in Base on Apple Watch, Base requests permission to save that completed workout to Apple Health. This lets the workout appear in your Health history and be available to other apps you authorize through Apple Health.
How app health data is handled
Processing happens on your iPhone and Apple Watch. Base keeps a protected local copy of the Health history needed for reliable counting and fast recalculation, including heart-rate timestamps and values, workout and Exercise Time records, and limited source or device metadata. Date-of-birth components are kept separately in a protected local profile.
Base Cardio LLC does not receive, remotely store, or have access to this health data. It is not uploaded to a Base server, stored by us in iCloud, or used for advertising or tracking. The only HealthKit write is a workout that you explicitly start in Base on Apple Watch. Base saves that workout to Apple Health when you finish it. Base does not synthesize or write heart-rate samples, modify existing Health records, or delete Health data.
You control Apple Health permission in iOS Settings. Revoking permission stops future access but does not delete information already stored locally by the app. Deleting Base removes its app container. When Apple Health reports that a previously read record was deleted, Base removes the corresponding local record during reconciliation.
Consumer health data
Some laws define collecting to include accessing or processing consumer health data on a person’s device. Our separate Consumer Health Data Privacy Policy explains the categories, sources, purposes, sharing, sale, and rights that apply under those laws.
App analytics, crash reports, and purchases
When the Base app has analytics enabled, it sends us information about how the app is used — which screens you open, which onboarding step you reach, whether the paywall loaded, and whether a purchase succeeded — along with crash and performance diagnostics. Two processors handle this on our behalf: PostHog (EU region) for product analytics and Sentry (EU region) for crashes. Nobody else watches your purchases: your subscription status is read on your own device from Apple’s records, and the sales figures we see are Apple’s own, which never identify anyone.
The app creates one identifier for the install and shares it with both so the information lines up. It is not an advertising identifier, it is not tied to any account, we do not use it to track you across other apps or websites, and it is deleted when you delete the app. Because that identifier joins the information together, we treat it as linked to you rather than anonymous.
Alongside each of those events, the analytics tool adds a few facts about the app itself: its version and build number, which version of iOS you are running, whether you are on a phone or a tablet, whether the app is a test build, and a session number that groups one visit together. Base removes the rest of what the tool would otherwise attach — your device model, screen size, language, time zone, and whether you are on Wi-Fi or cellular — before anything is sent.
Your Apple Health data is never included. No heart rate, resting heart rate, heart-rate zones, age, workouts, zone 2 minutes, weekly totals, goal results, or streaks leave your device — not as numbers, not as yes/no flags, not as ranges. The app also never records or uploads pictures of its own screens, because a picture of Base is a picture of your heart data.
You can turn all of this off in the app under You → App settings → Privacy → “Share usage data”. Turning it off stops both processors and discards the identifier. Turning it back on creates a brand new identifier, so what you did before is never reconnected to what you do after.
One honest exception, and it is only about crash reports. If the app crashed while your phone was offline, that report is already written down and waiting to upload. Switching sharing off stops anything new, but a report recorded before you switched it off may still finish uploading. It is a crash report from a moment when sharing was on, it contains none of your health data, and the crash tool we use gives us no way to delete it from the phone first. The usage-analytics side has no such gap — we delete its stored data on the spot.
Website waitlist and technical information
The waitlist is optional and separate from the app. If you join, we collect the waitlist email you submit along with the form’s consent version and source so we can document your request for Base launch and occasional product updates.
Netlify processes the form and hosts the website on our behalf. Netlify may process ordinary request and security information needed to deliver and protect the service, such as an IP address, browser information, timestamps, and request logs, under its own service terms and privacy commitments. We do not connect website information to Apple Health data.
We currently use no website analytics, advertising trackers, cross-site tracking technology, or analytics cookies.
Contacting support, and app diagnostics
If you email support from inside Base, a message is prepared for you with your app version and build, your device model and iOS version, and — when iOS has produced any — a short performance summary Base keeps on your device: how long the app took to launch, how often it stopped responding, and how many crash, hang, or disk-write reports iOS generated. Base does not put any Apple Health data in it: no zone 2 minutes, no goals or streaks, no heart rates, and no dates from your history. You always see the whole message first, and the performance summary is just text you can delete. Base never sends it for you: if your iPhone has Mail set up, the message opens in a composer inside Base and you decide whether to send it — though dismissing a composer can still leave a draft in your own Mail drafts — and otherwise Base hands the draft to whichever email app you use, where what happens next is up to that app.
What you write is your own. Please leave health details out of a support email if you can — we do not need them to help you. If you do include them, we treat them like the rest of the message: used only to answer you and fix the problem, never used for advertising or sold, and deleted along with the correspondence if you ask.
We hold support email as ordinary correspondence linked to your email address, and we keep it no longer than we need to resolve your issue — normally up to 24 months — unless you ask us to delete it sooner. Ask at the address below and we will delete it.
If you test Base through TestFlight, Apple shares tester information with us, and what we get depends on how you joined and what you send:
- Automatically, for every tester: a device identifier, information about how you used the build, and crash logs.
- Your name and email address: only if we invited you by email. If you joined through a public TestFlight link, Apple does not show us the name or email you enrolled with — though anything you type into feedback, including an email address, does reach us.
- Anything you choose to send: TestFlight feedback you submit — your comments and any screenshots — comes to us with the build and device details attached.
We use all of it only to run the test: to understand a crash, to reply to your feedback, and to know which build you were on. We do not use it for advertising, we do not sell it, and Apple's rules do not allow us to share TestFlight information with anyone else. We keep our copies while the test is running and for up to 12 months afterwards, then delete them, and we will delete them sooner if you ask — that covers the copies we hold, not Apple's own records, which Apple keeps under its own policy. You can stop testing at any time; note that stopping does not delete the build already on your device, and a build keeps working until it expires, so use Delete App if you want it gone.
Separately, Apple operates its own crash reporting for every app, and Base has not turned it off. There are two situations. If you use Base from the App Store, Apple sends us its crash reports only when you have Share With App Developers enabled in iOS Settings under Privacy & Security, Analytics & Improvements; those reports describe the technical state of a crash and carry no Apple Health data. We use them for one thing — finding and fixing the crash — and never for advertising, and we never sell them. They reach us through App Store Connect and Xcode, where Apple controls how long they stay available; the copies we download we keep no longer than we need to fix the problem, normally up to 12 months, and you can turn the whole thing off at any time in that iOS setting. If you test Base through TestFlight, Apple's collection is automatic and cannot be turned off by you, and what Apple may make available to us is broader — it can include your name and email address, a device identifier, usage information, and crash logs, as described in Apple's TestFlight privacy notice. We tell testers this when we invite them.
Purposes and legal bases
Where a law requires legal bases, we rely on your consent for waitlist messages; your request and our legitimate interest in answering you for support correspondence and the diagnostics the app pre-fills into it; your request, choices, and our contract with you to provide Base; our legitimate interests in operating and securing the website and answering requests; and legal obligations when applicable. You may withdraw waitlist consent at any time without affecting earlier lawful handling.
For the app’s usage analytics and crash reporting, which are on unless you turn them off, we rely on our legitimate interests in understanding whether Base works, finding out when it crashes, and seeing where people get stuck — balanced against a deliberately narrow collection: no health data at all, a random identifier rather than an account, no advertising use, no sale, and no tracking across other apps or websites. Turning off “Share usage data” in the app is how you object to that processing, and it takes effect immediately.
Service providers, Apple, and international processing
Netlify is our current website hosting and form service provider. Waitlist and technical website information may be processed in the United States and other locations where Netlify operates. Netlify states that it participates in the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework. When a restricted transfer is not covered by those frameworks, Netlify’s data processing agreement provides the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (UK IDTA).
You can review Netlify’s Privacy Statement and Data Processing Agreement, or email us for more information about these safeguards.
Apple independently operates Apple Health, the App Store, StoreKit, and App Store payments under Apple’s terms and privacy policy. We do not receive your payment-card information. The app receives entitlement information from Apple on your device so it can unlock the purchase you made.
Retention
App health information remains on your devices while needed for Base’s features and while the app is installed, subject to reconciliation when Apple Health reports a deletion. Uninstalling Base removes its app container. A workout Base saved to Apple Health remains in Apple Health until you delete it there.
We delete waitlist information when you unsubscribe or ask us to delete it. Otherwise, we keep it no longer than the earlier of 24 months after signup or 12 months after Base’s public launch. We may retain a minimal suppression record when necessary to honor an opt-out or meet a legal obligation.
We keep TestFlight tester information while the test programme runs and for up to 12 months after it ends, or until you ask us to delete it.
App usage analytics are held by PostHog in the EU under our project’s retention setting, which is 84 months. Crash and performance diagnostics are held by Sentry in the EU for the retention period that applies to error events under our current Sentry plan; Sentry sets that period, and we do not extend it. Neither ever receives information derived from Apple Health.
Both are keyed only to a random identifier created when you install Base — not your name, email, or account, and nothing we can connect to you unless you tell us it. Turning off “Share usage data” stops both immediately and discards that identifier, and deleting the app has the same effect. Everything recorded after you turn sharing back on is kept separate from anything recorded before, apart from the one crash-report exception described above.
That also marks the honest limit of what we can do on request: because the identifier is random and we hold nothing that ties it to your name or email, we normally cannot find one person’s records in order to delete them, and we will not ask you for more information about yourself in order to try. If you can tell us the identifier, we will ask both processors to erase what is held under it.
We keep support correspondence, including any diagnostics that were in the message you sent, for as long as needed to resolve your issue and normally no longer than 24 months, or until you ask us to delete it. The performance summary on your device holds only the last five summaries Base has built from what iOS reported. We store it in a file we mark for exclusion from backups, and Base never uploads it anywhere on its own. Deleting Base removes that file from your device.
Hosting and security logs follow Netlify’s applicable retention practices.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information we hold, and to withdraw consent. You may also have a right to appeal a refusal. Email hello@basecardio.com to make a request or privacy complaint. We may need to verify that the request concerns your email, and we will respond within the deadline required by applicable law.
You may complain to the privacy regulator where you live, including the Office of the Privacy Commissioner of Canada, the UK Information Commissioner’s Office, Ireland’s Data Protection Commission, the Office of the Australian Information Commissioner, New Zealand’s Office of the Privacy Commissioner, Singapore’s Personal Data Protection Commission, or South Africa’s Information Regulator. United States residents may also contact their state attorney general where applicable.
Children
Base is not directed to children under 13, and the website waitlist is not intended for anyone under 16. We do not knowingly collect a child’s waitlist email. If you believe a child submitted one, contact us and we will delete it.
Security
We use safeguards appropriate to the information we handle, including keeping app health processing on-device and limiting website collection. No system is perfectly secure, so we cannot guarantee absolute security.
Changes and contact
If this notice materially changes, we will update the effective date and provide additional notice where appropriate or legally required. We will request any consent required before using information for a materially different purpose.
Questions, requests, or complaints can be sent to hello@basecardio.com or mailed to the address above.